Draft a Professional GDPR Data Subject Access Request Response

Generate compliant, professional GDPR data request responses that protect your company and respect customer rights.

πŸ“ The Prompt

You are a customer support specialist trained in GDPR compliance at [COMPANY_NAME], operating in [JURISDICTION: EU / UK / both]. Draft a professional response to a data subject access request (DSAR) from [CUSTOMER_NAME] who has requested: [REQUEST_TYPE: access to their personal data / data deletion (right to erasure) / data portability / rectification of data / restriction of processing]. Request received on: [DATE_RECEIVED] Response deadline: [DEADLINE_DATE] Customer account status: [STATUS: active / inactive / deleted] Identity verification status: [VERIFIED: yes / pending / no] Structure the response as follows: 1. **Acknowledgment**: Confirm receipt of the request, reference the date received, and cite the relevant GDPR article (e.g., Article 15 for access, Article 17 for erasure). 2. **Identity verification** (if pending): Politely explain what additional verification is needed and why, listing acceptable documents. If already verified, skip this section. 3. **Scope of action**: Clearly describe what data categories you hold about the customer (e.g., account information, transaction history, communication logs, cookies/tracking data) and what action will be taken. 4. **Timeline**: State when the request will be fulfilled (within the 30-day GDPR window) and any factors that could extend this. 5. **Exceptions or limitations**: If any data cannot be provided or deleted (e.g., legal retention obligations, fraud prevention), explain the legal basis clearly and respectfully. 6. **Next steps**: Outline what the customer should expect and provide a direct contact for questions. 7. **Closing**: Professional and empathetic sign-off. Tone: Professional, transparent, and reassuring. Avoid legalese where possible while remaining legally accurate. Length: 250-350 words.

πŸ’‘ Tips for Better Results

Always verify the requester's identity before disclosing any personal dataβ€”this is a legal requirement. Keep a log of every DSAR response for audit purposes. Have your legal or DPO team review the template before first use, then use the AI output as a starting draft.

🎯 Use Cases

Customer support teams, data protection officers, and compliance managers use this when responding to GDPR data subject requests within legally mandated timeframes.

πŸ”— Related Prompts

🀝 Customer Support intermediate

Craft a Personalized VIP Customer Appreciation Message for High-Value Clients

Generate personalized VIP customer appreciation messages in multiple tones to deepen relationships with your highest-value clients.

🀝 Customer Support beginner

Customer Support Response Templates

Get 8 professional customer support templates covering complaints, refunds, bugs, and more.

🀝 Customer Support intermediate

Write a Professional Feature Request Acknowledgment Response

Respond to customer feature requests with a structured acknowledgment that validates their idea and sets clear expectations.

🀝 Customer Support intermediate

Draft an Account Reactivation Email to Win Back Inactive Customers

Create a persuasive account reactivation email that wins back inactive customers with empathy, value reminders, and clear next steps.

🀝 Customer Support beginner

Write Clear and Secure Password Reset Instructions for Customer Support

Generate step-by-step password reset instructions for customers, including troubleshooting tips and security best practices.

🀝 Customer Support beginner

Craft a Customer Milestone Celebration Email That Builds Loyalty

Write a personalized milestone celebration email that strengthens customer loyalty with stats, rewards, and warmth.